Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art objects, which allows remote attackers to execute arbitrary code via vectors related to a function pointer, aka "Excel Dangling Pointer Vulnerability."
http://dvlabs.tippingpoint.com/blog/2011/02/07/zdi-disclosure-microsoft
http://secunia.com/advisories/39122
http://secunia.com/advisories/43210
http://www.securitytracker.com/id?1025337
http://www.us-cert.gov/cas/techalerts/TA11-102A.html
http://www.vupen.com/english/advisories/2011/0940
http://zerodayinitiative.com/advisories/ZDI-11-040/
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-021
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12018
OR
cpe:2.3:a:microsoft:excel:2002:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:excel:2003:sp3:*:*:*:*:*:*
cpe:2.3:a:microsoft:office:2004:*:mac:*:*:*:*:*
cpe:2.3:a:microsoft:office:2008:*:mac:*:*:*:*:*
cpe:2.3:a:microsoft:open_xml_file_format_converter:*:*:mac:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
53378 | MS11-021: Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279) | Nessus | Windows : Microsoft Bulletins | high |
53374 | MS11-021 / MS11-022 / MS11-023: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2489279 / 2489283 / 2489293) (Mac OS X) | Nessus | MacOS X Local Security Checks | high |